
sigma-cli
The Sigma command line interface based on pySigma

The Sigma command line interface based on pySigma

Aggregated Zeek-format threat intelligence feeds with combined indicators from public and curated sources for continuous IDS and network threat…

Real-time network diagnostics in your terminal. One command, zero config, instant visibility.

A Flaw in SSH protocol message handling, a malicious actor could gain unauthorized access to affected systems and execute arbitrary commands without…

Wazuh detection rules for CVE-2026-73570, an OS command injection in Zimbra Collaboration Suite, monitoring web access logs and zimbra.log for…

Detects phi-structured C2 beacons that evade RITA and standard regularity-based detectors

Pre-execution intent verification for AI agents. Audits what your AI is about to do, not what it says. Zero dependencies, deterministic, hash-sealed.

Threat hunting command system for agentic IDEs

CVE-2026-24207 — NVIDIA Triton SageMaker auth bypass to unauth RCE. Detection script, bypass demo, RCE-chain PoC, and IDS rules.

Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.

Full exploit chain lab and Suricata IDS detection for CVE-2022-30190 (Follina) - MSDT RCE

Lightweight network intrusion detection engine capturing live traffic with libpcap. Detects SYN/ICMP floods, port scans, and signature-based web…

Berry Sentinel v5.0 — Advanced behavioral C2 and reverse shell detector for Linux/Windows/Unix systems. Features real-time connection analysis,…

Zeek detector for QuasarRat

A Zeek package to detect the Pingback malware ICMP tunnel command and control (C2) network traffic.

A Zeek based NetSupport detector. NetSupport is often abused by attackers in malware.

A Zeek based Mitre Caldera detector.

A Zeek based AsyncRAT malware detector.